Aggregator
Hackers Use Six-Layer Persistence to Maintain Access on Compromised FreePBX Systems
A hacker group known as INJ3CTOR3 has been running an active campaign against FreePBX systems, deploying a newly discovered PHP webshell called JOMANGY that uses six separate persistence layers to stay embedded on compromised servers. The campaign targets internet-exposed VoIP phone systems and routes calls through them at the victims’ expense, a scheme known as […]
The post Hackers Use Six-Layer Persistence to Maintain Access on Compromised FreePBX Systems appeared first on Cyber Security News.
FBI warns about fast-growing phishing kit targeting Microsoft 365 users
Kali365, which was first observed in April, abuses legitimate Microsoft device authorization pages to grant persistent access to cybercriminal-controlled applications.
The post FBI warns about fast-growing phishing kit targeting Microsoft 365 users appeared first on CyberScoop.
CVE-2026-33376 | Grafana OSS up to 13.0.1+security-00 Auth Proxy Feature Remote Code Execution (Nessus ID 316482 / WID-SEC-2026-1546)
CVE-2026-28380 | Grafana OSS up to 13.0.1+security-00 access control (Nessus ID 316482 / WID-SEC-2026-1546)
CVE-2026-33377 | Grafana OSS up to 13.0.1+security-00 access control (Nessus ID 316482 / WID-SEC-2026-1546)
CVE-2026-4426 | libarchive ISO File Parser pz_log2_bs incorrect bitwise shift of integer (Nessus ID 316487 / WID-SEC-2026-0803)
CVE-2026-45498 | Microsoft Defender Antimalware Platform denial of service (EUVD-2026-31102 / Nessus ID 316484)
CVE-2026-42897 | Microsoft Exchange Server cross site scripting (Nessus ID 316010 / WID-SEC-2026-1536)
Hackers Use NF-e Invoice Lures to Deliver Banana RAT Through Malicious Batch Files
A newly discovered banking trojan is targeting Brazilians by disguising itself as a legitimate electronic invoice. The malware, known as Banana RAT, uses fake NF-e (Nota Fiscal Eletronica) documents to trick victims into running malicious batch files that quietly install a powerful remote access tool on their Windows systems. The campaign has been active and […]
The post Hackers Use NF-e Invoice Lures to Deliver Banana RAT Through Malicious Batch Files appeared first on Cyber Security News.